--
-
---alert-before-pass process alert, drop, sdrop, or reject before pass; default is pass before alert, drop,…
-
-
--
-
---bpf <filter options> are standard BPF options, as seen in TCPDump
-
-
--
-
---c2x output hex for given char
-
-
--
-
---create-pidfile create PID file, even when not in Daemon mode
-
-
--
-
---daq <type> select packet acquisition module (default is pcap)
-
-
--
-
---daq-dir <dir> tell snort where to find desired DAQ
-
-
--
-
---daq-list list packet acquisition modules available in optional dir, default is static modules only
-
-
--
-
---daq-mode <mode> select the DAQ operating mode
-
-
--
-
---daq-var <name=value> specify extra DAQ configuration variable
-
-
--
-
---dirty-pig don’t flush packets on shutdown
-
-
--
-
---dump-builtin-rules [<module prefix>] output stub rules for selected modules
-
-
--
-
---dump-defaults [<module prefix>] output module defaults in Lua format
-
-
--
-
---dump-dynamic-rules output stub rules for all loaded rules libraries
-
-
--
-
---dump-version output the version, the whole version, and only the version
-
-
--
-
---enable-inline-test enable Inline-Test Mode Operation
-
-
--
-
---help list command line options
-
-
--
-
---help-commands [<module prefix>] output matching commands
-
-
--
-
---help-config [<module prefix>] output matching config options
-
-
--
-
---help-counts [<module prefix>] output matching peg counts
-
-
--
-
---help-module <module> output description of given module
-
-
--
-
---help-modules list all available modules with brief help
-
-
--
-
---help-options <option prefix> output matching command line option quick help (same as -?)
-
-
--
-
---help-plugins list all available plugins with brief help
-
-
--
-
---help-signals dump available control signals
-
-
--
-
---id-subdir create/use instance subdirectories in logdir instead of instance filename prefix
-
-
--
-
---id-zero use id prefix / subdirectory even with one packet thread
-
-
--
-
---list-buffers output available inspection buffers
-
-
--
-
---list-builtin <module prefix> output matching builtin rules
-
-
--
-
---list-gids [<module prefix>] output matching generators
-
-
--
-
---list-modules [<module type>] list all known modules of given type
-
-
--
-
---list-plugins list all known plugins
-
-
--
-
---logid <0xid> log Identifier to uniquely id events for multiple snorts (same as -G)
-
-
--
-
---lua <chunk> extend/override conf with chunk; may be repeated
-
-
--
-
---markup output help in asciidoc compatible format
-
-
--
-
---max-packet-threads <count> configure maximum number of packet threads (same as -z)
-
-
--
-
---nolock-pidfile do not try to lock Snort PID file
-
-
--
-
---nostamps don’t include timestamps in log file names
-
-
--
-
---pause wait for resume/quit command before processing packets/terminating
-
-
--
-
---pcap-dir <dir> a directory to recurse to look for pcaps - read mode is implied
-
-
--
-
---pcap-file <file> file that contains a list of pcaps to read - read mode is implied
-
-
--
-
---pcap-filter <filter> filter to apply when getting pcaps from file or directory
-
-
--
-
---pcap-list <list> a space separated list of pcaps to read - read mode is implied
-
-
--
-
---pcap-loop <count> read all pcaps <count> times; 0 will read until Snort is terminated
-
-
--
-
---pcap-no-filter reset to use no filter when getting pcaps from file or directory
-
-
--
-
---pcap-reload if reading multiple pcaps, reload snort config between pcaps
-
-
--
-
---pcap-reset ignored - for REG_TEST only
-
-
--
-
---pcap-show print a line saying what pcap is currently being read
-
-
--
-
---pedantic warnings are fatal
-
-
--
-
---plugin-path <path> where to find plugins
-
-
--
-
---process-all-events process all action groups
-
-
--
-
---rule <rules> to be added to configuration; may be repeated
-
-
--
-
---rule-to-hex output so rule header to stdout for text rule on stdin
-
-
--
-
---rule-to-text output plain so rule header to stdout for text rule on stdin
-
-
--
-
---run-prefix <pfx> prepend this to each output file
-
-
--
-
---script-path <path> where to find luajit scripts
-
-
--
-
---shell enable the interactive command line
-
-
--
-
---show-plugins list module and plugin versions
-
-
--
-
---skip <n> skip 1st n packets
-
-
--
-
---snaplen <snap> set snaplen of packet (same as -s)
-
-
--
-
---stdin-rules read rules from stdin until EOF or a line starting with END is read
-
-
--
-
---treat-drop-as-alert converts drop, sdrop, and reject rules into alert rules during startup
-
-
--
-
---treat-drop-as-ignore use drop, sdrop, and reject rules to ignore session traffic when not inline
-
-
--
-
---version show version number (same as -V)
-
-
--
-
---warn-all enable all warnings
-
-
--
-
---warn-flowbits warn about flowbits that are checked but not set and vice-versa
-
-
--
-
---warn-unknown warn about unknown symbols in your config
-
-
--
-
---x2c output ASCII char for given hex
-
-
--
-
--? <option prefix> output matching command line option quick help (same as --help-options)
-
-
--
-
--A <mode> set alert mode: none, cmg, or alert_*
-
-
--
-
--B <mask> obfuscated IP addresses in alerts and packet dumps using CIDR mask
-
-
--
-
--C print out payloads with character data only (no hex)
-
-
--
-
--D run Snort in background (daemon) mode
-
-
--
-
--E enable daemon restart
-
-
--
-
--G <0xid> (same as --logid)
-
-
--
-
--H make hash tables deterministic
-
-
--
-
--K <mode> logging mode
-
-
--
-
--M log messages to syslog (not alerts)
-
-
--
-
--N ignored - for REG_TEST only
-
-
--
-
--O obfuscate the logged IP addresses
-
-
--
-
--Q enable inline mode operation
-
-
--
-
--R <rules> include this rules file in the default policy
-
-
--
-
--S <n=v> set rules file variable n equal to value v
-
-
--
-
--T test and report on the current Snort configuration
-
-
--
-
--U use UTC for timestamps
-
-
--
-
--V (same as --version)
-
-
--
-
--W lists available interfaces
-
-
--
-
--X dump the raw packet data starting at the link layer
-
-
--
-
--c <conf> use this configuration
-
-
--
-
--d dump the Application Layer
-
-
--
-
--e display the second layer header info
-
-
--
-
--f turn off fflush() calls after binary log writes
-
-
--
-
--g <gname> run snort gid as <gname> group (or gid) after initialization
-
-
--
-
--i <iface>… list of interfaces
-
-
--
-
--j <port> to listen for telnet connections
-
-
--
-
--k <mode> checksum mode (all,noip,notcp,noudp,noicmp,none)
-
-
--
-
--l <logdir> log to this directory instead of current directory
-
-
--
-
--m <umask> set umask = <umask>
-
-
--
-
--n <count> stop after count packets
-
-
--
-
--q quiet mode - Don’t show banner and status report
-
-
+